longshot007
2008-08-22, 05:52
Below are Combofix and a fresh HJT Log after Combofix. What else do I need to do?
ComboFix 08-08-21.02 - stephen hamilton 2008-08-21 22:33:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1287 [GMT -4:00]
Running from: C:\Documents and Settings\stephen hamilton\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\#SharedObjects\XXFD77LT\interclick.com
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\#SharedObjects\XXFD77LT\interclick.com\ud.sol
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\matthew hamilton\Cookies\matthew_hamilton@2o7[2].txt
C:\Documents and Settings\matthew hamilton\Cookies\matthew_hamilton@ad.yieldmanager[2].txt
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\#SharedObjects\AYZULKHX\interclick.com
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\#SharedObjects\AYZULKHX\interclick.com\ud.sol
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch\config.cfg.99ff20dcfa0ff7fdd023698452e13c62
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@interclick[1].txt
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@trustedantivirus[1].txt
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@www.tv[1].txt
C:\Documents and Settings\stephen c hamilton\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\#SharedObjects\5FXBJU96\interclick.com
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\#SharedObjects\5FXBJU96\interclick.com\ud.sol
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\stephen hamilton\Application Data\SpeedRunner
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA11004U.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA149GDZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA1B5PJO.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA4CEVT8.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA5LFNTZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA6WHTOI.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA7GIUVD.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA7SJCR7.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA8CMBI3.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA979FIN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA9DVJKB.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA9Y5PRQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAA2IWQN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAB0EK2I.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CABVJM9J.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAC6JSO1.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CACDA3RZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAD0LIKE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAERQJLD.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAFTHL60.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAGP7REX.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAH21D61.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIG6I1M.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIMHSFA.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIPMTFY.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJ5ZQE6.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJ6URQQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJMSPMZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJS6RPN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKNEX1S.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKUGG7J.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKY4WQQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CALIQIE3.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CALYXA4G.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAM175VA.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAMAZC2X.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAN6LSHI.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CANG56VQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAO5UCI1.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAPM8OHE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAT2QWMH.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CATPF93Y.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CATVHF5D.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUQRJQE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUVA83K.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUXXWME.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAWRR3YW.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAXXIUDT.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAYL6F8P.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAYRCQBK.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAZ1QS1X.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[1].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[10].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[11].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[2].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[3].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[4].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[5].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[6].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[7].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[8].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[9].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@antispywaremaster[1].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@systemerrorfixer[2].txt
C:\Documents and Settings\stephen hamilton\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\stephen hamilton\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\stephen hamilton\services.exe
C:\Program Files\CPV
C:\Program Files\CPV\CPV7.dll.lzma
C:\Program Files\NoDNS
C:\Program Files\NoDNS\UnInstall.exe
C:\Program Files\Spcron
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\gbRve12
C:\Temp\gbRve12\csLioes.log
C:\temp\tn3
C:\WINDOWS\17PHolmes1000106.exe
C:\WINDOWS\BM73d4b093.txt
C:\WINDOWS\BM73d4b093.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\MyWebEx
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atarm.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atas32.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasanot.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasctrl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasnt40.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atcarmcl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atjpeg60.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atkbctl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atlchat.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atmemmgr.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atnetext.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atpack.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\attp.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atwbxui.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\ieatgpc.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwm.ini
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmcliun.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmHook.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmproxy.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmupd.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\ratrace.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\raurl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\uilibres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\wbxcrypt.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\webexmgr.dll
C:\WINDOWS\system32\adzgalore-remove.exe
C:\WINDOWS\system32\aqVreo18
C:\WINDOWS\system32\ayyyaGgh.ini
C:\WINDOWS\system32\ayyyaGgh.ini2
C:\WINDOWS\system32\bIPWaJjl.ini
C:\WINDOWS\system32\bIPWaJjl.ini2
C:\WINDOWS\system32\cpmsky-uninst.exe
C:\WINDOWS\system32\cqxrjeop.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\fOWwvGgh.ini
C:\WINDOWS\system32\fOWwvGgh.ini2
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\ifqueogg.ini
C:\WINDOWS\system32\ijTvxxbc.ini
C:\WINDOWS\system32\ijTvxxbc.ini2
C:\WINDOWS\system32\JjlRrXbc.ini
C:\WINDOWS\system32\JjlRrXbc.ini2
C:\WINDOWS\system32\jkgtcepn.ini
C:\WINDOWS\system32\jsyhfaqo.exe
C:\WINDOWS\system32\jtqibudq.ini
C:\WINDOWS\system32\kjlRuBeg.ini
C:\WINDOWS\system32\kkUtutwa.ini
C:\WINDOWS\system32\kkUtutwa.ini2
C:\WINDOWS\system32\lpbkybrb.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\meivxjqe.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\myss_sb_uninstall.exe
C:\WINDOWS\system32\ngorsevo.ini
C:\WINDOWS\system32\nmgkilli.ini
C:\WINDOWS\system32\nulntsdw.exe
C:\WINDOWS\system32\ohkopqlq.exe
C:\WINDOWS\system32\oidijhnu.ini
C:\WINDOWS\system32\OqYcdfii.ini
C:\WINDOWS\system32\OqYcdfii.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pAGQYcdd.ini
C:\WINDOWS\system32\pAGQYcdd.ini2
C:\WINDOWS\system32\pendapec.ini
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~1\?ppPatch\
C:\WINDOWS\system32\prckquct.exe
C:\WINDOWS\system32\qnnvdtgj.exe
C:\WINDOWS\system32\QXbHNqru.ini
C:\WINDOWS\system32\rxjmxpbw.exe
C:\WINDOWS\system32\sgtvbnxm.ini
C:\WINDOWS\system32\sisfffyd.ini
C:\WINDOWS\system32\tatuvkas.ini
C:\WINDOWS\system32\tDgPoUvw.ini
C:\WINDOWS\system32\tDgPoUvw.ini2
C:\WINDOWS\system32\txbpdyje.ini
C:\WINDOWS\system32\UFMSsvut.ini
C:\WINDOWS\system32\UFMSsvut.ini2
C:\WINDOWS\system32\uvaluldu.ini
C:\WINDOWS\system32\VEMUuBeg.ini
C:\WINDOWS\system32\VEMUuBeg.ini2
C:\WINDOWS\system32\vfyftpni.exe
C:\WINDOWS\system32\XELlRXbc.ini
C:\WINDOWS\system32\XELlRXbc.ini2
C:\WINDOWS\system32\ybdJRqss.ini
C:\WINDOWS\system32\ybdJRqss.ini2
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2008-07-22 to 2008-08-22 )))))))))))))))))))))))))))))))
.
2008-08-21 22:30 . 2008-08-21 22:30 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-21 22:30 . 2008-08-21 22:30 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-21 22:28 . 2008-08-21 22:28 <DIR> d-------- C:\Program Files\Java
2008-08-21 22:28 . 2008-08-21 22:28 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-21 22:28 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-14 20:47 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-07-28 21:01 . 2008-07-28 21:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-26 17:03 . 2008-07-26 17:03 <DIR> d-------- C:\Program Files\Zone Labs
2008-07-26 17:02 . 2008-07-26 17:03 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-07-24 23:35 . 2008-07-28 20:45 745 --a------ C:\WINDOWS\wininit.ini
2008-07-23 21:41 . 2008-08-21 22:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-23 21:41 . 2008-07-23 23:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 02:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 02:00 --------- d-----w C:\Program Files\dl_cats
2008-08-15 12:02 --------- d-----w C:\Program Files\McAfee
2008-08-15 07:23 --------- d-----w C:\Documents and Settings\stephen c hamilton\Application Data\buildburnmeta
2008-08-15 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\third lies itch ford
2008-07-22 00:46 --------- d-----w C:\Program Files\Dell Network Assistant
2008-07-22 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-07-21 02:31 --------- d-----w C:\Program Files\Common Files\SystemErrorFixer
2008-07-21 02:31 --------- d-----w C:\Program Files\Common Files\fmfq
2008-07-21 01:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-21 01:00 --------- d-----w C:\Program Files\Lavasoft
2008-07-21 00:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-20 12:58 --------- d-----w C:\Program Files\SiteAdvisor
2008-07-19 22:17 --------- d-----w C:\Program Files\Google
2008-04-26 19:35 8,492 ----a-w C:\Documents and Settings\stephen c hamilton\Application Data\wklnhst.dat
2008-04-23 20:05 6,016 ----a-w C:\Documents and Settings\stephen hamilton\Application Data\wklnhst.dat
2008-03-30 21:14 65,800 ----a-w C:\Documents and Settings\stephen c hamilton\Application Data\GDIPFONTCACHEV1.DAT
2008-02-03 23:10 726 ----a-w C:\Documents and Settings\matthew hamilton\Application Data\wklnhst.dat
2006-12-27 00:32 251 ----a-w C:\Program Files\wt3d.ini
2006-12-09 01:48 0 ---ha-w C:\Documents and Settings\All Users\Application Data\gwseh.dat
2008-04-20 22:31 104 --sh--r C:\WINDOWS\system32\3DC58E69D8.sys
2008-04-20 22:32 5,852 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8d44ef1d-1234-3013-d63c-59613604e451}]
2008-07-15 12:06 313856 --a------ C:\WINDOWS\system32\nsr7E.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-16 10:39 7323648]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 09:15 151552]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12 94208]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 08:51 286720]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 07:34 299008]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-06-15 06:03 307200]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 12:17 106496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 21:46 98304]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-08-24 17:57 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 12:20 282624 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-08 21:45:05 7168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-08 21:44:51 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec Core LC"=2 (0x2)
"ProtectionService"=2 (0x2)
"NVSvc"=2 (0x2)
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"ELNKUpdateService"=2 (0x2)
"EarthLinkSafeConnectAgent"=3 (0x3)
"dvpapi"=2 (0x2)
"dlcx_device"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"ADSService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\dlcxcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Datel\\PSP Max Media Manager Pro\\PSPMMM.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
S1 tdii;tdii;C:\WINDOWS\system32\drivers\tdii.sys []
S2 0268391218801733mcinstcleanup;McAfee Application Installer Cleanup (0268391218801733);C:\WINDOWS\TEMP\026839~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 05:39]
S4 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-05-18 16:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - 0268391218801733MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
2008-08-22 C:\WINDOWS\Tasks\A8D91DE8915E92F8.job
- c:\docume~1\stephe~2\applic~1\buildb~1\Roam Vc Cool.exe []
2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-18 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
BHO-{1F97FD11-CDA3-4F72-AE0C-05D27A8EB659} - C:\WINDOWS\system32\hgGvwWOf.dll
HKCU-Run-Yahoo! Pager - C:\Program Files\Yahoo!\Messenger\ypager.exe
HKCU-Run-fmfq - C:\PROGRA~1\COMMON~1\fmfq\fmfqm.exe
HKLM-Run-AIMPro - C:\Program Files\AIM\AIM Pro\aimpro.exe
HKLM-Run-strpmon - C:\Program Files\Common Files\SystemErrorFixer\strpmon.exe dm=http://systemerrorfixer.com ad=http://systemerrorfixer.com
HKLM-Run-70e7830f - C:\WINDOWS\system32\ejydpbxt.dll
Notify-ssqPhFwt - ssqPhFwt.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.charter.com/
R0 -: HKLM-Main,Search Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 22:39:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-08-21 22:43:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-22 02:43:37
Pre-Run: 197,237,964,800 bytes free
Post-Run: 197,545,504,768 bytes free
411 --- E O F --- 2008-08-15 07:03:07
================**** HJT LOG BELOW ****====================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:01 PM, on 8/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0061208
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: adzgalore - {8d44ef1d-1234-3013-d63c-59613604e451} - C:\WINDOWS\system32\nsr7E.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: McAfee Application Installer Cleanup (0268391218801733) (0268391218801733mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\026839~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 9338 bytes
Link to earlier topic: http://forums.spybot.info/showthread.php?t=31714
ComboFix 08-08-21.02 - stephen hamilton 2008-08-21 22:33:01.1 - NTFSx86
Microsoft Windows XP Professional 5.1.2600.2.1252.1.1033.18.1287 [GMT -4:00]
Running from: C:\Documents and Settings\stephen hamilton\Desktop\ComboFix.exe
* Created a new restore point
* Resident AV is active
WARNING -THIS MACHINE DOES NOT HAVE THE RECOVERY CONSOLE INSTALLED !!
.
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\LocalService\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\#SharedObjects\XXFD77LT\interclick.com
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\#SharedObjects\XXFD77LT\interclick.com\ud.sol
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\matthew hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\matthew hamilton\Cookies\matthew_hamilton@2o7[2].txt
C:\Documents and Settings\matthew hamilton\Cookies\matthew_hamilton@ad.yieldmanager[2].txt
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\#SharedObjects\AYZULKHX\interclick.com
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\#SharedObjects\AYZULKHX\interclick.com\ud.sol
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\stephen c hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch\config.cfg.99ff20dcfa0ff7fdd023698452e13c62
C:\Documents and Settings\stephen c hamilton\Application Data\WinTouch\wintouch.cfg
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@interclick[1].txt
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@trustedantivirus[1].txt
C:\Documents and Settings\stephen c hamilton\Cookies\stephen_c_hamilton@www.tv[1].txt
C:\Documents and Settings\stephen c hamilton\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\#SharedObjects\5FXBJU96\interclick.com
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\#SharedObjects\5FXBJU96\interclick.com\ud.sol
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com
C:\Documents and Settings\stephen hamilton\Application Data\macromedia\Flash Player\macromedia.com\support\flashplayer\sys\#interclick.com\settings.sol
C:\Documents and Settings\stephen hamilton\Application Data\SpeedRunner
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA11004U.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA149GDZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA1B5PJO.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA4CEVT8.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA5LFNTZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA6WHTOI.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA7GIUVD.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA7SJCR7.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA8CMBI3.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA979FIN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA9DVJKB.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CA9Y5PRQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAA2IWQN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAB0EK2I.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CABVJM9J.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAC6JSO1.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CACDA3RZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAD0LIKE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAERQJLD.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAFTHL60.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAGP7REX.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAH21D61.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIG6I1M.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIMHSFA.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAIPMTFY.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJ5ZQE6.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJ6URQQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJMSPMZ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAJS6RPN.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKNEX1S.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKUGG7J.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAKY4WQQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CALIQIE3.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CALYXA4G.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAM175VA.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAMAZC2X.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAN6LSHI.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CANG56VQ.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAO5UCI1.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAPM8OHE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAT2QWMH.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CATPF93Y.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CATVHF5D.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUQRJQE.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUVA83K.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAUXXWME.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAWRR3YW.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAXXIUDT.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAYL6F8P.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAYRCQBK.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen hamilton@CAZ1QS1X.txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[1].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[10].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[11].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[2].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[3].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[4].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[5].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[6].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[7].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[8].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@ad.yieldmanager[9].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@antispywaremaster[1].txt
C:\Documents and Settings\stephen hamilton\Cookies\stephen_hamilton@systemerrorfixer[2].txt
C:\Documents and Settings\stephen hamilton\Local Settings\Temporary Internet Files\bestwiner.stt
C:\Documents and Settings\stephen hamilton\Local Settings\Temporary Internet Files\CPV.stt
C:\Documents and Settings\stephen hamilton\services.exe
C:\Program Files\CPV
C:\Program Files\CPV\CPV7.dll.lzma
C:\Program Files\NoDNS
C:\Program Files\NoDNS\UnInstall.exe
C:\Program Files\Spcron
C:\Temp\1cb
C:\Temp\1cb\syscheck.log
C:\Temp\gbRve12
C:\Temp\gbRve12\csLioes.log
C:\temp\tn3
C:\WINDOWS\17PHolmes1000106.exe
C:\WINDOWS\BM73d4b093.txt
C:\WINDOWS\BM73d4b093.xml
C:\WINDOWS\cookies.ini
C:\WINDOWS\Downloaded Program Files\MyWebEx
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atarm.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atas32.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasanot.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasctrl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atasnt40.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atcarmcl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atjpeg60.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atkbctl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atlchat.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atmemmgr.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atnetext.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atpack.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\attp.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\atwbxui.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\ieatgpc.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwm.ini
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmcliun.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmHook.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmproxy.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\mwmupd.exe
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\ratrace.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\raurl.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\uilibres.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\wbxcrypt.dll
C:\WINDOWS\Downloaded Program Files\MyWebEx\491\webexmgr.dll
C:\WINDOWS\system32\adzgalore-remove.exe
C:\WINDOWS\system32\aqVreo18
C:\WINDOWS\system32\ayyyaGgh.ini
C:\WINDOWS\system32\ayyyaGgh.ini2
C:\WINDOWS\system32\bIPWaJjl.ini
C:\WINDOWS\system32\bIPWaJjl.ini2
C:\WINDOWS\system32\cpmsky-uninst.exe
C:\WINDOWS\system32\cqxrjeop.exe
C:\WINDOWS\system32\drivers\core.cache.dsk
C:\WINDOWS\system32\fOWwvGgh.ini
C:\WINDOWS\system32\fOWwvGgh.ini2
C:\WINDOWS\system32\gside.exe
C:\WINDOWS\system32\ifqueogg.ini
C:\WINDOWS\system32\ijTvxxbc.ini
C:\WINDOWS\system32\ijTvxxbc.ini2
C:\WINDOWS\system32\JjlRrXbc.ini
C:\WINDOWS\system32\JjlRrXbc.ini2
C:\WINDOWS\system32\jkgtcepn.ini
C:\WINDOWS\system32\jsyhfaqo.exe
C:\WINDOWS\system32\jtqibudq.ini
C:\WINDOWS\system32\kjlRuBeg.ini
C:\WINDOWS\system32\kkUtutwa.ini
C:\WINDOWS\system32\kkUtutwa.ini2
C:\WINDOWS\system32\lpbkybrb.exe
C:\WINDOWS\system32\mcrh.tmp
C:\WINDOWS\system32\meivxjqe.exe
C:\WINDOWS\system32\MSINET.oca
C:\WINDOWS\system32\mysidesearch_sidebar_uninstall.exe
C:\WINDOWS\system32\myss_sb_uninstall.exe
C:\WINDOWS\system32\ngorsevo.ini
C:\WINDOWS\system32\nmgkilli.ini
C:\WINDOWS\system32\nulntsdw.exe
C:\WINDOWS\system32\ohkopqlq.exe
C:\WINDOWS\system32\oidijhnu.ini
C:\WINDOWS\system32\OqYcdfii.ini
C:\WINDOWS\system32\OqYcdfii.ini2
C:\WINDOWS\system32\pac.txt
C:\WINDOWS\system32\pAGQYcdd.ini
C:\WINDOWS\system32\pAGQYcdd.ini2
C:\WINDOWS\system32\pendapec.ini
C:\WINDOWS\system32\pppatc~1
C:\WINDOWS\system32\pppatc~1\?ppPatch\
C:\WINDOWS\system32\prckquct.exe
C:\WINDOWS\system32\qnnvdtgj.exe
C:\WINDOWS\system32\QXbHNqru.ini
C:\WINDOWS\system32\rxjmxpbw.exe
C:\WINDOWS\system32\sgtvbnxm.ini
C:\WINDOWS\system32\sisfffyd.ini
C:\WINDOWS\system32\tatuvkas.ini
C:\WINDOWS\system32\tDgPoUvw.ini
C:\WINDOWS\system32\tDgPoUvw.ini2
C:\WINDOWS\system32\txbpdyje.ini
C:\WINDOWS\system32\UFMSsvut.ini
C:\WINDOWS\system32\UFMSsvut.ini2
C:\WINDOWS\system32\uvaluldu.ini
C:\WINDOWS\system32\VEMUuBeg.ini
C:\WINDOWS\system32\VEMUuBeg.ini2
C:\WINDOWS\system32\vfyftpni.exe
C:\WINDOWS\system32\XELlRXbc.ini
C:\WINDOWS\system32\XELlRXbc.ini2
C:\WINDOWS\system32\ybdJRqss.ini
C:\WINDOWS\system32\ybdJRqss.ini2
C:\x.dat
C:\z.dat
.
((((((((((((((((((((((((((((((((((((((( Drivers/Services )))))))))))))))))))))))))))))))))))))))))))))))))
.
-------\Legacy_CMDSERVICE
-------\Legacy_NETWORK_MONITOR
((((((((((((((((((((((((( Files Created from 2008-07-22 to 2008-08-22 )))))))))))))))))))))))))))))))
.
2008-08-21 22:30 . 2008-08-21 22:30 <DIR> d-------- C:\Program Files\Common Files\Adobe AIR
2008-08-21 22:30 . 2008-08-21 22:30 <DIR> d-------- C:\Program Files\Common Files\Adobe
2008-08-21 22:28 . 2008-08-21 22:28 <DIR> d-------- C:\Program Files\Java
2008-08-21 22:28 . 2008-08-21 22:28 <DIR> d-------- C:\Program Files\Common Files\Java
2008-08-21 22:28 . 2008-06-10 02:32 73,728 --a------ C:\WINDOWS\system32\javacpl.cpl
2008-08-14 20:47 . 2008-05-01 10:30 331,776 --------- C:\WINDOWS\system32\dllcache\msadce.dll
2008-07-28 21:01 . 2008-07-28 21:01 <DIR> d-------- C:\Program Files\Trend Micro
2008-07-26 17:03 . 2008-07-26 17:03 <DIR> d-------- C:\Program Files\Zone Labs
2008-07-26 17:02 . 2008-07-26 17:03 <DIR> d-------- C:\WINDOWS\Internet Logs
2008-07-24 23:35 . 2008-07-28 20:45 745 --a------ C:\WINDOWS\wininit.ini
2008-07-23 21:41 . 2008-08-21 22:02 <DIR> d-------- C:\Program Files\Spybot - Search & Destroy
2008-07-23 21:41 . 2008-07-23 23:13 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2008-08-22 02:00 --------- d---a-w C:\Documents and Settings\All Users\Application Data\TEMP
2008-08-22 02:00 --------- d-----w C:\Program Files\dl_cats
2008-08-15 12:02 --------- d-----w C:\Program Files\McAfee
2008-08-15 07:23 --------- d-----w C:\Documents and Settings\stephen c hamilton\Application Data\buildburnmeta
2008-08-15 07:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\third lies itch ford
2008-07-22 00:46 --------- d-----w C:\Program Files\Dell Network Assistant
2008-07-22 00:46 --------- d-----w C:\Documents and Settings\All Users\Application Data\SingleClick Systems
2008-07-21 02:31 --------- d-----w C:\Program Files\Common Files\SystemErrorFixer
2008-07-21 02:31 --------- d-----w C:\Program Files\Common Files\fmfq
2008-07-21 01:01 --------- d-----w C:\Documents and Settings\All Users\Application Data\Lavasoft
2008-07-21 01:00 --------- d-----w C:\Program Files\Lavasoft
2008-07-21 00:59 --------- d-----w C:\Program Files\Common Files\Wise Installation Wizard
2008-07-20 12:58 --------- d-----w C:\Program Files\SiteAdvisor
2008-07-19 22:17 --------- d-----w C:\Program Files\Google
2008-04-26 19:35 8,492 ----a-w C:\Documents and Settings\stephen c hamilton\Application Data\wklnhst.dat
2008-04-23 20:05 6,016 ----a-w C:\Documents and Settings\stephen hamilton\Application Data\wklnhst.dat
2008-03-30 21:14 65,800 ----a-w C:\Documents and Settings\stephen c hamilton\Application Data\GDIPFONTCACHEV1.DAT
2008-02-03 23:10 726 ----a-w C:\Documents and Settings\matthew hamilton\Application Data\wklnhst.dat
2006-12-27 00:32 251 ----a-w C:\Program Files\wt3d.ini
2006-12-09 01:48 0 ---ha-w C:\Documents and Settings\All Users\Application Data\gwseh.dat
2008-04-20 22:31 104 --sh--r C:\WINDOWS\system32\3DC58E69D8.sys
2008-04-20 22:32 5,852 --sha-w C:\WINDOWS\system32\KGyGaAvL.sys
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
REGEDIT4
[HKEY_LOCAL_MACHINE\~\Browser Helper Objects\{8d44ef1d-1234-3013-d63c-59613604e451}]
2008-07-15 12:06 313856 --a------ C:\WINDOWS\system32\nsr7E.dll
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"MSMSGS"="C:\Program Files\Messenger\msmsgs.exe" [2004-10-13 12:24 1694208]
"CTSyncU.exe"="C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe" [2006-08-07 10:06 700416]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-10 07:00 15360]
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray"="C:\WINDOWS\ehome\ehtray.exe" [2005-09-29 16:01 67584]
"NvCplDaemon"="C:\WINDOWS\system32\NvCpl.dll" [2006-06-16 10:39 7323648]
"IAAnotif"="C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2006-07-06 09:15 151552]
"DMXLauncher"="C:\Program Files\Dell\Media Experience\DMXLauncher.exe" [2005-10-05 05:12 94208]
"ISUSPM Startup"="C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" [2005-06-10 11:44 249856]
"ISUSScheduler"="C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" [2005-06-10 11:44 81920]
"dlcxmon.exe"="C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe" [2006-06-14 08:51 286720]
"MemoryCardManager"="C:\Program Files\Dell Photo AIO Printer 926\memcard.exe" [2006-06-27 07:34 299008]
"FaxCenterServer"="C:\Program Files\Dell PC Fax\fm3032.exe" [2006-06-15 06:03 307200]
"DLCXCATS"="C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll" [2006-06-07 12:17 106496]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2006-12-08 21:46 98304]
"mcagent_exe"="C:\Program Files\McAfee.com\Agent\mcagent.exe" [2007-11-01 19:12 582992]
"SiteAdvisor"="C:\Program Files\SiteAdvisor\6261\SiteAdv.exe" [2007-08-24 17:57 36640]
"McENUI"="C:\PROGRA~1\McAfee\MHN\McENUI.exe" [2007-11-30 05:42 1164576]
"McAfee Backup"="C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe" [2007-01-16 13:59 4838952]
"MBkLogOnHook"="C:\Program Files\McAfee\MBK\LogOnHook.exe" [2007-01-08 11:22 20480]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe" [2008-06-10 04:27 144784]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2008-06-12 02:38 34672]
"SigmatelSysTrayApp"="stsystra.exe" [2006-07-24 12:20 282624 C:\WINDOWS\stsystra.exe]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
Dell Network Assistant.lnk - C:\WINDOWS\Installer\{0240BDFB-2995-4A3F-8C96-18D41282B716}\Icon0240BDFB3.exe [2006-12-08 21:45:05 7168]
Digital Line Detect.lnk - C:\Program Files\Digital Line Detect\DLG.exe [2006-12-08 21:44:51 24576]
Microsoft Office.lnk - C:\Program Files\Microsoft Office\Office10\OSA.EXE [2001-02-13 03:01:04 83360]
[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"InstallVisualStyle"= C:\WINDOWS\Resources\Themes\Royale\Royale.msstyles
"InstallTheme"= C:\WINDOWS\Resources\Themes\Royale.theme
[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\services]
"Symantec Core LC"=2 (0x2)
"ProtectionService"=2 (0x2)
"NVSvc"=2 (0x2)
"LiveUpdate Notice Service"=2 (0x2)
"LiveUpdate Notice Ex"=2 (0x2)
"LiveUpdate"=3 (0x3)
"IAANTMON"=2 (0x2)
"gusvc"=3 (0x3)
"GoogleDesktopManager"=3 (0x3)
"ELNKUpdateService"=2 (0x2)
"EarthLinkSafeConnectAgent"=3 (0x3)
"dvpapi"=2 (0x2)
"dlcx_device"=3 (0x3)
"Creative Service for CDROM Access"=2 (0x2)
"comHost"=3 (0x3)
"CLTNetCnService"=2 (0x2)
"ccSetMgr"=2 (0x2)
"ccEvtMgr"=2 (0x2)
"Automatic LiveUpdate Scheduler"=2 (0x2)
"ADSService"=3 (0x3)
[HKEY_LOCAL_MACHINE\software\microsoft\security center]
"AntiVirusDisableNotify"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\McAfeeFirewall]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001
[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile]
"EnableFirewall"= 0 (0x0)
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\system32\\sessmgr.exe"=
"C:\\Program Files\\Messenger\\msmsgs.exe"=
"C:\\Program Files\\LimeWire\\LimeWire.exe"=
"C:\\WINDOWS\\system32\\dlcxcoms.exe"=
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"C:\\StubInstaller.exe"=
"C:\\Program Files\\Datel\\PSP Max Media Manager Pro\\PSPMMM.exe"=
"C:\\Program Files\\Common Files\\McAfee\\MNA\\McNASvc.exe"=
"C:\\Program Files\\Dell Network Assistant\\ezi_hnm2.exe"=
[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"10421:UDP"= 10421:UDP:SingleClick Discovery Protocol
"10426:UDP"= 10426:UDP:SingleClick ICC
S1 tdii;tdii;C:\WINDOWS\system32\drivers\tdii.sys []
S2 0268391218801733mcinstcleanup;McAfee Application Installer Cleanup (0268391218801733);C:\WINDOWS\TEMP\026839~1.EXE C:\PROGRA~1\COMMON~1\McAfee\INSTAL~1\cleanup.ini []
S3 NAL;Nal Service ;C:\WINDOWS\system32\Drivers\iqvw32.sys [2006-06-05 05:39]
S4 dlcx_device;dlcx_device;C:\WINDOWS\system32\dlcxcoms.exe [2006-05-18 16:36]
[HKEY_CURRENT_USER\software\microsoft\windows\currentversion\explorer\mountpoints2\{361ac05d-0e0d-11da-9aa9-806d6172696f}]
\Shell\AutoRun\command - E:\setup.exe
*Newly Created Service* - 0268391218801733MCINSTCLEANUP
.
Contents of the 'Scheduled Tasks' folder
2008-08-22 C:\WINDOWS\Tasks\A8D91DE8915E92F8.job
- c:\docume~1\stephe~2\applic~1\buildb~1\Roam Vc Cool.exe []
2008-08-15 C:\WINDOWS\Tasks\McDefragTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
2008-08-18 C:\WINDOWS\Tasks\McQcTask.job
- c:\PROGRA~1\mcafee\mqc\QcConsol.exe [2007-12-04 13:32]
.
- - - - ORPHANS REMOVED - - - -
BHO-{1F97FD11-CDA3-4F72-AE0C-05D27A8EB659} - C:\WINDOWS\system32\hgGvwWOf.dll
HKCU-Run-Yahoo! Pager - C:\Program Files\Yahoo!\Messenger\ypager.exe
HKCU-Run-fmfq - C:\PROGRA~1\COMMON~1\fmfq\fmfqm.exe
HKLM-Run-AIMPro - C:\Program Files\AIM\AIM Pro\aimpro.exe
HKLM-Run-strpmon - C:\Program Files\Common Files\SystemErrorFixer\strpmon.exe dm=http://systemerrorfixer.com ad=http://systemerrorfixer.com
HKLM-Run-70e7830f - C:\WINDOWS\system32\ejydpbxt.dll
Notify-ssqPhFwt - ssqPhFwt.dll
.
------- Supplementary Scan -------
.
R0 -: HKCU-Main,Start Page = hxxp://www.charter.com/
R0 -: HKLM-Main,Search Bar = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R1 -: HKCU-Internet Connection Wizard,ShellNext = iexplore
R1 -: HKCU-SearchURL,(Default) = hxxp://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
.
**************************************************************************
catchme 0.3.1361 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2008-08-21 22:39:22
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
--------------------- DLLs Loaded Under Running Processes ---------------------
PROCESS: C:\WINDOWS\explorer.exe
-> C:\Program Files\SiteAdvisor\6261\saHook.dll
.
------------------------ Other Running Processes ------------------------
.
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\ehome\ehrecvr.exe
C:\WINDOWS\ehome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
C:\PROGRA~1\COMMON~1\McAfee\MNA\McNASvc.exe
C:\PROGRA~1\COMMON~1\McAfee\McProxy\McProxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\Mcshield.exe
C:\Program Files\McAfee\MPF\MpfSrv.exe
C:\Program Files\McAfee\MSK\msksrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\wdfmgr.exe
C:\WINDOWS\ehome\mcrdsvc.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\ehome\ehmsas.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
.
**************************************************************************
.
Completion time: 2008-08-21 22:43:41 - machine was rebooted
ComboFix-quarantined-files.txt 2008-08-22 02:43:37
Pre-Run: 197,237,964,800 bytes free
Post-Run: 197,545,504,768 bytes free
411 --- E O F --- 2008-08-15 07:03:07
================**** HJT LOG BELOW ****====================
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:46:01 PM, on 8/21/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16705)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell Network Assistant\hnm_svc.exe
C:\Program Files\McAfee\MBK\MBackMonitor.exe
C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
C:\Program Files\McAfee\MPF\MPFSrv.exe
C:\Program Files\McAfee\MSK\MskSrver.exe
C:\Program Files\SiteAdvisor\6261\SAService.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\dllhost.exe
c:\PROGRA~1\mcafee.com\agent\mcagent.exe
C:\WINDOWS\ehome\ehtray.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
C:\Program Files\Dell\Media Experience\DMXLauncher.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe
C:\Program Files\Dell Photo AIO Printer 926\memcard.exe
C:\Program Files\SiteAdvisor\6261\SiteAdv.exe
C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Dell Network Assistant\ezi_hnm2.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\system32\notepad.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.charter.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/yme/*http://www.yahoo.com/ext/search/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Search,Default_Page_URL = www.google.com/ig/dell?hl=en&client=dell-usuk-rel&channel=us&ibd=0061208
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ie/defaults/su/yme/*http://www.yahoo.com
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: adzgalore - {8d44ef1d-1234-3013-d63c-59613604e451} - C:\WINDOWS\system32\nsr7E.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe
O4 - HKLM\..\Run: [DMXLauncher] C:\Program Files\Dell\Media Experience\DMXLauncher.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [dlcxmon.exe] "C:\Program Files\Dell Photo AIO Printer 926\dlcxmon.exe"
O4 - HKLM\..\Run: [MemoryCardManager] "C:\Program Files\Dell Photo AIO Printer 926\memcard.exe"
O4 - HKLM\..\Run: [FaxCenterServer] "C:\Program Files\Dell PC Fax\fm3032.exe" /s
O4 - HKLM\..\Run: [DLCXCATS] rundll32 C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\DLCXtime.dll,_RunDLLEntry@16
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkey
O4 - HKLM\..\Run: [SiteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"
O4 - HKLM\..\Run: [McENUI] C:\PROGRA~1\McAfee\MHN\McENUI.exe /hide
O4 - HKLM\..\Run: [McAfee Backup] C:\Program Files\McAfee\MBK\McAfeeDataBackup.exe
O4 - HKLM\..\Run: [MBkLogOnHook] C:\Program Files\McAfee\MBK\LogOnHook.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [CTSyncU.exe] "C:\Program Files\Creative\Sync Manager Unicode\CTSyncU.exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Dell Network Assistant.lnk = ?
O4 - Global Startup: Digital Line Detect.lnk = ?
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: (no name) - {B205A35E-1FC4-4CE3-818B-899DBBB3388C} - C:\Program Files\Common Files\Microsoft Shared\Encarta Search Bar\ENCSBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {80B626D6-BC34-4BCF-B5A1-7149E4FD9CFA} (UnoCtrl Class) - http://zone.msn.com/bingame/zpagames/GAME_UNO1.cab60096.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {C487F60B-59B9-47D9-BFDF-AB26786F8823} - http://zone.msn.com/bingame/zpagames/zpa_stoo.cab62201.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O23 - Service: McAfee Application Installer Cleanup (0268391218801733) (0268391218801733mcinstcleanup) - Unknown owner - C:\WINDOWS\TEMP\026839~1.EXE (file missing)
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Advanced Networking Service (hnmsvc) - SingleClick Systems - C:\Program Files\Dell Network Assistant\hnm_svc.exe
O23 - Service: MBackMonitor - McAfee - C:\Program Files\McAfee\MBK\MBackMonitor.exe
O23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exe
O23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mna\mcnasvc.exe
O23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exe
O23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exe
O23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exe
O23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exe
O23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exe
O23 - Service: McAfee Anti-Spam Service (MSK80Service) - McAfee, Inc. - C:\Program Files\McAfee\MSK\MskSrver.exe
O23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exe
--
End of file - 9338 bytes
Link to earlier topic: http://forums.spybot.info/showthread.php?t=31714